Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VDR Enhancements #16

Open
Scanteianu opened this issue May 13, 2024 · 9 comments
Open

VDR Enhancements #16

Scanteianu opened this issue May 13, 2024 · 9 comments

Comments

@Scanteianu
Copy link
Contributor

see comments

@Scanteianu
Copy link
Contributor Author

add new source for cves - reference original ojvg page

@Scanteianu
Copy link
Contributor Author

use credentials when querying NIST to prevent throttling

@Scanteianu
Copy link
Contributor Author

translate version number into URI for temurin release

@Scanteianu
Copy link
Contributor Author

figure out why affects only works some of the time

@Scanteianu
Copy link
Contributor Author

add rating from ojvg as well

@Scanteianu
Copy link
Contributor Author

Scanteianu commented May 13, 2024

see if versions can take a range - use semantic versioning - anything affecting major.minor is assumed to also impact all earlier versions of that major version

@Scanteianu
Copy link
Contributor Author

Scanteianu commented May 13, 2024

@netomi thinks we might be able to use https://hub.docker.com/r/owasp/dependency-check to avoid having to download from NVD entirely

here is an example how it could be used from an action: https://github.com/dependency-check/DependencyCheck_Builder

@netomi
Copy link

netomi commented May 13, 2024

actually the correct image should be https://hub.docker.com/r/owasp/dependency-check-action that is updated daily with the latest CVE data.

@Scanteianu
Copy link
Contributor Author

Scanteianu commented Aug 19, 2024

see if versions can take a range - use semantic versioning - anything affecting major.minor is assumed to also impact all earlier versions of that major version

converted this to a new issue. #50

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants